> For the complete documentation index, see [llms.txt](https://copilot-docs.bugbase.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://copilot-docs.bugbase.ai/enterprise/attack-surface/target-assets.md).

# Target Assets

Target assets are root entities used as starting points for discovery and assessment.

<figure><img src="/files/bS9LDmJZQZM1yO55rylJ" alt=""><figcaption></figcaption></figure>

## Supported Manual Root Target Types

The Target Entities page supports manual root-target creation for these entity types:

| Type         | Example         | Used for                                    |
| ------------ | --------------- | ------------------------------------------- |
| **Domain**   | `example.com`   | External discovery and external assessment. |
| **Subnet**   | `10.10.0.0/16`  | Internal discovery and internal assessment. |
| **APK File** | uploaded `.apk` | Mobile application analysis.                |

IP addresses are graph entities discovered during scanning or inventory enrichment. They are not manual root targets on this page.

## External Domains

Add root domains only. Do not add full URLs or paths as root domains.

After adding a domain, check **Settings -> Domains** to confirm it is allowed by your external scope rules.

## Internal Subnets

Internal subnets can be added manually as root targets or discovered from connected agents. Add or select only CIDR ranges approved for the engagement.

## Deleting or Changing Targets

Before deleting a root target, confirm whether reports, schedules, attack paths, or graph data still depend on it. For external scope changes, update **Settings -> Domains** and **Settings -> Trajectories** as well.
